|
The Web Hacking Incidents Database Last update:07 November 2007
List of incidents of class Insufficient Authorization
Other
WASC threat
classifications: Abuse of Functionality, Brute Force, Content Spoofing, Credential/Session Prediction, Cross-site Scripting, Defacement, Denial of Service, Directory Indexing, HTTP Response Splitting, Information Leakage, Insufficient Anti-automation, Insufficient Authentication, Insufficient Authorization, Insufficient Process Validation, Insufficient Session Expiration, Known Vulnerabity, Misconfiguration, OS Commanding, Other, Path Traversal, Phishing, Predictable Resource Location, Redirection, SQL Injection, Unknown, Weak Password Recovery Validation, Worm
There are 22 incidents of class Insufficient Authorization
Date: 02 October 2007
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
Personal information on anyone who worked or volunteered for the Pembroke schools in the last four years was accessible via the Internet because of a weakness in the district's computer system. The information, including names, birth dates and Social Security numbers, was available from May until Oct. 2, when school officials learned of the problem.
References:
Date: 25 July 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization
In a classic case of lack of proper separation between the production and development sites, an application under production with lack of proper authentication and authorization was installed on a hospital's public web site, enabling anyone to query a database of 51,000 names, addresses and social security numbers.
References:
Date: 23 July 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization
Fox News left non public files on a directory accessible to everyone on their web server.
References:
Date: 03 June 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization
A spreadsheet left on the web site of the US office of national intelligence includes secret information on the total budget of the US intelligence. Interestingly the not all the required information appears in the document, but combined with other pieces of information made available prior, the total number can be calculated.
This is a very interesting example of the sensitivity of partial data or small pieces of information and not just the big secrets.
References:
Date: 30 May 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization, Predictable Resource Location
Google left some files at the wrong place at the wrong time. These files includes, surprisingly, database connection strings, including a user name and a password. Hardly news, but this time it is Google.
References:
Date: 12 July 2006
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
Altiris seems to have designed their servers so that it is easy to both access their customers upload as well as find out their e-mail addresses.
References:
Date: 30 June 2006
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization, Predictable Resource Location
MySpace bulletins, presumably accessible only to the social network of the originator can be access by anyone by iterating through a message id query parameter.
References:
Date: 13 January 2006
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization, Predictable Resource Location
Documents uploaded to GSA site where accessed using a predictable sequential identifier without requiring special permissions. The documents where available both for viewing and modifying. The site was in service for more than 18 months until the vulnerability was discovered.
References:
Date: 07 November 2005
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
References:
Date: 02 November 2005
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization
Business wire allowed access to non published press releases.
References:
Date: 28 October 2005
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization, Other
Configuration mistake left an unprotected unused virtual host. No details on the configuration problems given.
References:
Date: 05 July 2005
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization, OS Commanding, SQL Injection
A person who discovered an SQL injection vulnerability in a USC system and informed security focus about the flaw was criminally charged with breaking into the system.
References:
Date: 27 May 2005
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
Files containing sensitive information left unprotected on the web server
References:
Date: 10 March 2005
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization
References:
Date: 14 June 2004
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authentication, Insufficient Authorization
A billing information system required only phone number and zip code to pull up account details
References:
Date: 04 March 2004
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization
Previously moderated weather announcements could be changed by the user
References:
Date: 02 February 2004
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
References:
Date: 02 February 2004
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
References:
Date: 02 February 2004
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
References:
Date: 26 January 2004
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
References:
Date: 24 October 2003
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Insufficient Authorization
View other customers orders by changing a sequential number within a URL parameter
References:
Date: 21 September 2002
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authorization, Predictable Resource Location
References:
This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.
|